A vulnerability has been discovered in BigProf Online Invoicing System 2.6, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /inventory/suppliers_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous JavaScript payloads on the system that will be triggered when the page loads.
Metrics
Affected Vendors & Products
References
History
Thu, 21 Nov 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
MITRE
Status: PUBLISHED
Assigner: INCIBE
Published: 2023-11-30T13:55:24.467Z
Updated: 2024-11-21T19:36:23.455Z
Reserved: 2023-11-30T10:46:07.063Z
Link: CVE-2023-6433
Vulnrichment
Updated: 2024-08-02T08:28:22.072Z
NVD
Status : Modified
Published: 2023-11-30T14:15:21.897
Modified: 2024-11-21T08:43:51.127
Link: CVE-2023-6433
Redhat
No data.